Engineering Notes

Git Bisect and Blame: Binary-Searching Your Way to “When Did This Break?”

Last time we looked at what actually happens between git add and git commit — the mechanics of the moment a commit gets created. This time we shift focus to a different kind of question: given a long history of past commits, how do you track down the one that introduced a specific bug? git blame and git bisect both dig into that history, but they’re suited to very different situations. git blame: following one line’s history directly Running git blame <file> lists, for every line in that file, the most recent commit that touched it — hash, author, and date included. If you already suspect a particular line is …

Read more
Engineering Notes

JWT and Session Tokens Explained: Stateless vs. Stateful Authentication

Two articles back, we covered cookie+nonce authentication, and last time we looked at how WordPress’s login cookie is actually a hybrid: signature verification is fully self-contained, but revocation depends on a server-side list of valid tokens. This time we look at the opposite end of the design spectrum: JWT (JSON Web Token), which aims for authentication that is fully stateless — no server-side token list at all. Comparing it against WordPress’s hybrid model makes the trade-off between stateful and stateless authentication much easier to see. What a JWT actually is: three dot-separated parts A JWT looks like a single string split into three parts by dots — xxxxx.yyyyy.zzzzz. These correspond …

Read more
Engineering Notes

CORS Explained: Why Browsers Block Cross-Origin API Requests

Anyone who has wired up a browser-side call to an API on a different domain has probably hit the red has been blocked by CORS policy message in the console — even though the server responded just fine. The browser is the one refusing to hand the response over. This article walks through the same-origin policy that causes this, and what CORS (Cross-Origin Resource Sharing) actually does to relax it safely. What “origin” means Note: an origin is the combination of a URL’s scheme (https://), hostname (wpmm.jp), and port. The path (/blog/, etc.) doesn’t count. https://wpmm.jp and https://en.wpmm.jp are different origins because the hostname differs; https://wpmm.jp and http://wpmm.jp are different …

Read more
Engineering Notes

Environment Variables and .env Files: What Wins When They Conflict?

When building a Python application, configuration values tend to live in one of three places: real OS environment variables, a .env file, or a hard-coded default in the code itself. These three can conflict, and when a value doesn’t seem to be “taking effect,” the cause is usually a misunderstanding of which one wins. This article walks through the resolution order between the three, and why it’s designed the way it is. What a .env file actually is Note: a .env file is a plain text file listing KEY=value pairs, one per line. It’s used to keep environment-specific or sensitive values — API keys, database connection strings — out of …

Read more
Engineering Notes

How Python’s venv Works — Why It Keeps Projects From Fighting Over the System Python

How Python’s venv Works — Why It Keeps Projects From Fighting Over the System Python Anyone who has worked with Python tooling has run into “virtual environments” (venv) sooner or later. A single command, python3 -m venv .venv, creates a directory that most Python projects treat as a given. What is that directory actually doing, and why has it become such a standard part of the workflow? This post looks at the problem venv solves and how it works under the hood. The Problem: Projects Sharing One Python Installation Working on multiple Python projects on the same machine eventually runs into a conflict: one project needs version 2 of a …

Read more
WordPress Maintenance

Image Optimization and WebP Basics: Why WebP Is Smaller, and How Browsers Decide to Use It

It’s often cited that the biggest drag on WordPress page speed isn’t code at all — it’s images. The same-looking photo can end up dramatically smaller in file size depending on whether it stays as JPEG/PNG or gets converted to WebP. This post looks at why WebP tends to be lighter, how browsers negotiate which format to load, and how WordPress itself has adopted the format over time. Why WebP Is Smaller: A Different Compression Approach JPEG, standardized back in 1992, is built on discrete cosine transform (DCT) compression. WebP, introduced by Google in 2010, takes a different route: it repurposes the intra-frame compression techniques from the VP8 video codec …

Read more
WordPress Maintenance

Cookie and Session Authentication Basics — What Happens Behind a wp-admin Login

The previous article covered how REST API requests inside wp-admin are protected by a combination of cookies and nonces. This time we go one level deeper: what actually happens when you “log in,” and why does entering a password once keep you authenticated across dozens of page loads afterward? We’ll also look at how WordPress’s approach differs from the more common server-side session model. What happens the moment you click “Log In” When you submit the wp-admin login form, wp_signon() first checks the submitted password against the hashed password stored in the database — nothing unusual so far. Once authentication succeeds, wp_set_auth_cookie() issues an authentication cookie to the browser. From …

Read more
WordPress Maintenance

REST API Authentication: Cookie+Nonce vs. Application Passwords

WordPress’s REST API (covered in an earlier article) mixes two kinds of endpoints: some that anyone can read without authenticating, and others that reject you outright unless you’re logged in. Inside wp-admin, the browser is quietly firing off requests to that same API the whole time you’re editing — and yet you never re-enter your password for each one. This article looks at the mechanism behind that: cookie+nonce authentication, and a separate mechanism built for a different purpose, Application Passwords. What authenticates a request inside wp-admin When you log into WordPress, your browser receives an authentication cookie named wordpress_logged_in_*. From then on, every request your browser sends to that same …

Read more
Engineering Notes

Queues and Thread Pools — Why Submission Order and Completion Order Aren’t the Same

Write code that tries to SSH into several sites in parallel and you’ll quickly run into two questions: how many connections should run at once, and in what order should the results come back? In Python, the foundation for both is the standard library’s queue module, and the concurrent.futures.ThreadPoolExecutor built on top of it. This article looks at how the two relate, and at a property that’s easy to overlook: the order tasks are submitted in is not the same as the order they finish in. What queue.Queue actually is Note: queue.Queue is a FIFO (first-in, first-out) data structure for safely passing items between threads. Conceptually it’s no different from …

Read more
Engineering Notes

Git’s Staging Area — What Actually Happens Between `git add` and `git commit`

Edit a file, run git add ., then git commit -m “…” — for most people these two commands feel like a single operation performed in two keystrokes. But why are they separate commands at all? What happens if you edit the file again after git add but before git commit? Many developers who use Git daily can’t answer either question cleanly. This article walks through the staging area, the mechanism sitting between those two commands. The three-area mental model Note: A common way to understand Git is the three-layer model — the working directory, the staging area (also called the index), and the repository. A change has to pass …

Read more